Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sign and verify binaries included in Pulumi releases #11645

Open
3 tasks
AaronFriel opened this issue Dec 13, 2022 · 0 comments
Open
3 tasks

Sign and verify binaries included in Pulumi releases #11645

AaronFriel opened this issue Dec 13, 2022 · 0 comments
Assignees
Labels
kind/enhancement Improvements or new features

Comments

@AaronFriel
Copy link
Member

AaronFriel commented Dec 13, 2022

Following up on #11310, we should introduce cosign into the CI workflows for pulumi-java, pulumi-yaml, and pulumi-dotnet, and use cosign verify to validate that we are retrieving the correct binaries from those repositories.

  • pulumi-yaml
  • pulumi-java
  • pulumi-dotnet
@AaronFriel AaronFriel added the kind/enhancement Improvements or new features label Dec 13, 2022
@AaronFriel AaronFriel added this to the 0.83 milestone Dec 13, 2022
@AaronFriel AaronFriel self-assigned this Dec 13, 2022
@mikhailshilkov mikhailshilkov removed this from the 0.83 milestone Jan 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/enhancement Improvements or new features
Projects
None yet
Development

No branches or pull requests

2 participants